Objective 1.1
SAA-C03Design secure access to AWS resources.
Objective 1.1 sits in Design Secure Architectures, which carries 30% of the Solutions Architect Associate exam. The questions below are original, written from the official objective title above, and each explanation cites the Amazon Web Services (AWS) page it rests on.
Objective title verbatim from the official objectives. Amazon Web Services (AWS) exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
An application on EC2 needs read access to an S3 bucket. Your team forbids long-lived credentials on instances. What do you configure?
Correct.
Checked against docs.aws.amazon.com, August 2026Concept
Credentials that live on a host outlive the host. Where a compute service can hand an identity to your code at runtime, the design that stores nothing survives imaging, cloning and staff turnover.
Why B
Compute services deliver short-term keys through the metadata endpoint, and the SDK default provider chain finds them with no file on the disk. Rotation happens without anyone scheduling it.
Source
AWS docs: Security best practices in IAM, checked August 2026When you're building on an AWS compute service, such as Amazon EC2 or Lambda, AWS delivers the temporary credentials of an IAM role to that compute resource. Applications written using an AWS SDK will discover and use these temporary credentials to access AWS resources, and there is no need to distribute long lived credentials for an IAM user to your workloads running on AWS…
Now you: objective 1.1 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
An OU-level SCP leaves Athena out of its allow list. An account admin then attaches AdministratorAccess to a developer. What happens when the developer queries Athena?
Sample question 2 of 3
Your organization attaches an SCP at the root denying a region. Weeks later, auditors find users in the management account still working in that region. Why?
Sample question 3 of 3
Your team gives a role an identity policy allowing every S3 action and a permissions boundary allowing DynamoDB actions. Which calls can the role make?
Full Solutions Architect Associate question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.